Description
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-4816 Vulnerability (CVE-2015-4816)
PHP Other Vulnerability (CVE-2007-2511)
MySQL CVE-2019-2420 Vulnerability (CVE-2019-2420)
WordPress Plugin All In One Favicon Cross-Site Scripting (4.6)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1000395)